High severity8.8NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-75574
CVE-2026-75574
Description
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and submit the form to execute an arbitrary operating-system command as the account running PHP.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <4.2.2
Patches
Vulnerability mechanics
References
2News mentions
1- Grav CMS: Eight Vulnerabilities Including Path Traversal and Auth Bypass Disclosed TogetherVypr Intelligence · Aug 25, 2026